CVE-2025-54905: Microsoft Word Information Disclosure Vulnerability
Microsoft Word Information Disclosure Vulnerability
Other sources
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54905?
CVE-2025-54905 is considered a medium severity vulnerability due to its potential to disclose information to unauthorized users.
How do I fix CVE-2025-54905?
To resolve CVE-2025-54905, you should update your Microsoft Office applications to the latest version as detailed in the official security updates.
Which products are affected by CVE-2025-54905?
CVE-2025-54905 affects multiple versions of Microsoft Word, Office LTSC, and SharePoint including Word 2016, Office 2019, and Office LTSC 2024.
Can CVE-2025-54905 lead to data theft?
Yes, CVE-2025-54905 can enable unauthorized access to sensitive information, facilitating data theft.
Is there a workaround for CVE-2025-54905?
No effective workaround is available for CVE-2025-54905; the only resolution is to apply the provided patches.